
The Police National Legal Database, an online legal reference platform used for more than 30 years by all 43 Home Office police forces in England and Wales as well as the British Transport Police, has confirmed a data breach that exposed contact information belonging to police officers, staff and other criminal justice professionals. The compromised data was published on the dark web, and the National Crime Agency is assisting with the investigation alongside private cybersecurity firms.
The database disclosed that names, organizations and work email addresses tied to police officers, staff, criminal justice professionals, government partners and customers were compromised and posted online. The organization stated there is no evidence that passwords or other security credentials were affected.
The breach also struck Ask the Police, a public question-and-answer service hosted on the same platform, exposing the names and email addresses of members of the public who had submitted inquiries through the site. That exposure creates two separate categories of risk: officers now face a heightened threat of phishing attempts built around their verified names, agencies and work emails, while members of the public who contacted police services have had that contact made visible on criminal forums.
The database’s most recent annual summary recorded 108,429 police registrations, offering a rough sense of scale, though the organization has not disclosed how many individuals were actually included in the breached dataset, nor has it released a timeline for when the intrusion began or a full account of how much data was taken.
The organization emphasized that it functions as a source of legal information and services for police forces and criminal justice bodies rather than a crime-recording system, and stated it does not hold confidential information related to victims, witnesses or offenders. It said all affected organizations were notified and given guidance, and that the incident was reported to the Information Commissioner’s Office.
The extortion group ExfilSquad listed the database as a victim on its leak site on July 26, claiming to have stolen roughly 1.9 gigabytes of data comprising approximately 135,000 records, split between 114,000 database subscribers and 21,000 Ask the Police users. The group also demanded a ransom to prevent the release of the remaining stolen material. The database has not attributed the intrusion to ExfilSquad or confirmed how the attackers gained access. ExfilSquad has also claimed a separate attack on American semiconductor company Analog Devices. The intrusion was reportedly detected on Sunday, July 26.
Cybersecurity firm VenariX examined samples tied to 11 of ExfilSquad’s 15 claimed victims and found structures consistent with Microsoft Dataverse in all of them, pointing to a possible pattern involving misconfigured Microsoft Power Pages portals, public-facing sites where overly permissive table access settings can leave data exposed to unauthenticated visitors.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543